Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URL

Đang mở Phù hợp với người mới
#4,914 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@DawnofGenX đang làm issue này rồi.

Từ ngày 30/9/2026.

  • #4918 của @DawnofGenX — đang mở

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
api, backend

Hướng nghiên cứu

Bắt đầu trong server.py tại các dòng 127 và 262-288, sau đó tái hiện yêu cầu prompts/get với URL không hợp lệ được nêu trong issue. So sánh cách xử lý prompt với việc xác thực mô hình Fetch được công cụ sử dụng và xác minh rằng đầu vào không hợp lệ trả về JSON-RPC -32602 cùng một thông báo rõ ràng, trong khi các URL hợp lệ vẫn trả về nội dung trang.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Describe the bug

The fetch tool validates url through the Fetch model, so a malformed URL comes back as a normal isError: true result. The fetch prompt passes arguments["url"] straight to fetch_url (server.py:262-265) and catches only McpError (server.py:267). fetch_url converts only httpx.HTTPError (server.py:127), and httpx.InvalidURL is not an HTTPError, so it escapes both handlers. With raise_exceptions=False (server.py:288), the SDK's low-level server then answers with a JSON-RPC error whose code is 0 and whose message is the raw exception text.

To Reproduce

mcp-server-fetch 0.6.3 (commit f46d957), mcp 1.29.0 (as in uv.lock), Python 3.14, Windows 11. After initialize, send over stdio:

{"jsonrpc": "2.0", "id": 3, "method": "prompts/get", "params": {"name": "fetch", "arguments": {"url": "http://[::1"}}}

Response:

{"jsonrpc": "2.0", "id": 3, "error": {"code": 0, "message": "Invalid port: ':1'"}}

The same URL through the tool is handled cleanly:

{"jsonrpc": "2.0", "id": 4, "method": "tools/call", "params": {"name": "fetch", "arguments": {"url": "http://[::1"}}}
isError: true — "1 validation error for Fetch\nurl\n  Input should be a valid URL, invalid IPv6 address ..."

Expected behavior

An invalid prompt argument should produce a proper parameter error (-32602, INVALID_PARAMS) with a clear message, consistent with the tool. Code 0 is the SDK's generic fallback for unhandled exceptions, so a client can't tell a bad argument from a server fault.

Suggested fix

Validate the prompt's url the same way the tool does before fetching:

url = arguments["url"]  # current code; replace with:
try:
    url = str(Fetch(url=arguments["url"]).url)
except ValueError as e:
    raise McpError(ErrorData(code=INVALID_PARAMS, message=str(e)))

With this change, the request above returns -32602 with the validation message, and a valid URL still returns the page content (checked locally).

Additional context

Related: #3359 / #3515 (malformed input handling). I found this while testing a static checker for MCP error handling, then reproduced it by hand with a raw JSON-RPC client (no MCP client library involved). Happy to open a PR with this change if that's useful.

Ngôn ngữ chính
TypeScript
Star
91k
Fork
11.8k
Merge trung bình
6 giờ 47 phút
Pull request đã merge (30 ngày)
74

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của modelcontextprotocol/servers

Tất cả issue của modelcontextprotocol/servers

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.